CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Laundry Bear is exploiting CVE-2025-66376 in unpatched Zimbra Collaboration Suite servers to steal emails, credentials, 2FA tokens, address books, and app passwords from Western government and critical-sector targets. The same day’s highest-risk signals span autonomous AI agent abuse, telecom surveillance of US military phones, ransomware use of a Microsoft Defender flaw, and another live DeFi exploit.
CVE-2025-66376 stands out because Zimbra patched the XSS flaw in November 2025, yet Russian state-backed operators are still using it against exposed servers. The campaign targets email itself: correspondence, credentials, second-factor material, and app passwords that can sustain espionage long after initial access.
OpenAI’s reported sandbox-escape incident and Iran’s SS7-linked tracking of US military phones show how privileged systems remain attractive when boundaries are weak. Microsoft Defender CVE-2026-33825 has moved into ransomware tradecraft, while Allbridge Core’s $1.65 million Solana pool drain reinforces that active exploitation is not limited to enterprise software.
Editorial: Recommended Actions
01
PRIORITY
Patch Zimbra Collaboration Suite servers against CVE-2025-66376 immediately and prioritize any internet-facing ZCS webmail service used by government, NGO, NATO-linked, Ukrainian, European, or U.S. organizations. Laundry Bear is exploiting unpatched Zimbra servers in a zero-click espionage campaign to steal email correspondence, credentials, 2FA tokens, address books, and app passwords, making delayed remediation a direct account-compromise and intelligence-loss risk.
02
PRIORITY
Deploy Microsoft’s April 14, 2026 fix for Microsoft Defender CVE-2026-33825 on Windows systems and treat unpatched hosts as ransomware exposure. CISA added the BlueHammer flaw to its Known Exploited Vulnerabilities catalog after confirming ransomware use, and the bug lets an authenticated low-privilege attacker gain SYSTEM access on Windows; enterprises should prioritize endpoints where local compromise could become domain or server compromise.
03
PRIORITY
Update affected WordPress Core deployments and take public WordPress sites through an emergency compromise check, especially versions in the 6.8.x and 6.9.0 through 7.0.1 ranges. Pakistan National CERT warned attackers are actively exploiting CVE-2026-63030 and CVE-2026-60137, with public proof-of-concept code available and a chain that can compromise websites without authentication through the REST API and WP_Query SQL injection issue.
04
PRIORITY
Remove mrmustard 0.7.4 from builds and rotate any SSH private keys, AWS credentials, and Kubernetes configuration secrets present on systems that installed it. StepSecurity reports the PyPI package version was trojanized after a maintainer GitHub account takeover and CI publishing abuse, and its payload exfiltrated developer secrets and installed persistence; users of 0.7.4 should assume compromise rather than waiting for evidence of misuse.
05
PRIORITY
Remove PLCs from direct internet exposure and review OT traffic now if you operate U.S. water, energy, or other critical infrastructure environments using Siemens, Schneider Electric, or Rockwell Automation devices. U.S. agencies warned Iran-linked actors are targeting OT environments for persistent access; administrators were specifically advised to use secure gateways and firewalls and review logs for indicators and suspicious traffic on OT ports 44818, 2222, 102, and 502.
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_